SECOPS-PRO · Question #37
A custom PowerShell command is detected by Cortex XDR as a behavioral threat, and the administrator has confirmed it as a false positive. What is the most operationally efficient way to allow this…
The correct answer is B. Create an alert exception based on CGO process path and command arguments. Creating an alert exception based on CGO process path and command arguments allows the PowerShell command to run without triggering detections, operationally efficiently.
Question
A custom PowerShell command is detected by Cortex XDR as a behavioral threat, and the administrator has confirmed it as a false positive. What is the most operationally efficient way to allow this command to run and not be detected by Cortex XDR?
Options
- ACreate an alert exclusion based on CGO hash, signer, and process path.
- BCreate an alert exception based on CGO process path and command arguments.
- CRight click on the alert and create an alert exclusion rule.
- DAdd the SHA256 hash to the allow list.
How the community answered
(43 responses)- A7% (3)
- B72% (31)
- C16% (7)
- D5% (2)
Explanation
Creating an alert exception based on CGO process path and command arguments allows the PowerShell command to run without triggering detections, operationally efficiently.
Topics
Community Discussion
No community discussion yet for this question.